Authentic8 Blog Category: Security

Ideas That Become Obvious In Hindsight

Interview: Authentic8 Co-founder and CEO Scott Petry on Leo Laporte's TWiT.tv

Were you excited when Apple presented the Newton mobile device to the world, a glimpse into a future starring the iPhone? Or perhaps relieved when the email Spam Wars were won by Postini, a Silicon Valley startup later bought by Google, where it became the core of Gmail?

The ideas and concepts that drove both breakthrough innovations initially faced ridicule (in the case of Newton) and skepticism. What they have in common is that today, they are obvious in hindsight.

What they also share is a name: Scott Petry. His career took him from Apple's Newton team to founding and later selling Postini - which solved the email spam problem - to Google and from there to his current role as Co-founder and CEO of Authentic8, which pioneered remote browser isolation in the cloud.

Do we have a theme here? Leo Laporte thinks so. The award-winning tech journalist and founder

How to Detect Browser Extensions

Working on new methods and tools to identify browser exploits, I recently came across a common question again in a forum: "Is it possible to detect what browser extensions I have installed?"

That information would be of value to various people for several reasons. Online attackers and snoops stand to gain most from it. Examples:

  • Browser extension details can help fingerprint the client from others, as in: "This client uses a Google Translate browser extension. This other client does not."
  • Plugin information can also aid in targeted client exploitation, as in: "This this client has version 2.0.6 of the [bleep] password manager installed, with working exploits A, B, and C."
  • Addon identification can also be leveraged to hijack the local browser, as in: "This developer's Gmail account has been pwned; let's use it to push a malicious update."


Sounds far-fetched? I wish it were. Check out our blog posts with real-life examples: JavaScript Template Attacks, Password Manager Extension Exploit, and

DoD's Cybersecurity Maturity Model Certification: Are Smaller Companies Prepared?

New requirements mean contractors will have to pay to play. What does this mean for small businesses in the defense industry?

The cybersecurity posture of the Defense Industrial Base (DIB) supply chain is only as strong as its weakest contractor. When considering the DIB supply chain includes 300,000 contractors with sensitive government data, and around 290,000 of them are not subject to strict cybersecurity requirements or oversight, something needs to change.

Leading that change is the Office of the Under Secretary of Defense for Acquisition and Sustainment - OUSD(A&S) - which has developed the Cybersecurity Maturity Model Certification (CMMC), an agile set of unified cybersecurity standards to ensure the security of government data on DIB networks.

Illustration for Cybersecurity Maturity Model Certification blog post: CMMS Seal

Illustration: CMMC Seal

CMMC will enable the government to verify contractors have adequate security protocols in place to protect non-public Federal Contract Information and more sensitive Controlled Unclassified Information.

How CMMC Aims to Unify Cybersecurity  

The most recent draft version of

What’s the ROI of Threat Hunting?

How can IT security threat hunters measure success? That is one of the core questions raised by the new SANS 2019 Threat Hunting Survey, which was co-sponsored by Authentic8.

*

The  answer may lie in a strategy and tool selection that avoids mission and  cost creep, and results in measurable effects - and savings - to prove  it.

That’s our main takeaway from this year’s Threat Hunting Survey. Co-authors Mathias Fuchs and Joshua Lemon capture the different  needs and challenges within organizations that are just starting their cyber threat hunting program, versus those who are honing their skills and programs.

Definitions of Threat Hunting

What is threat hunting? The SANS survey results document a wide variety of methodologies, spending  priorities, tools deployed, training needs - and opinions about what  constitutes effective threat hunting practices.

"Many organizations use an alert-driven approach to threat hunting or use indicators of compromise [IoCs] to guide their hunts," says Mathias Fuchs, a SANS instructor and threat

Operation “Shields Up”: Web Isolation in the U.S. Military

How can government organizations, private enterprises, and academic institutions minimize the cybersecurity and privacy risks associated with accessing the internet from desktop or mobile devices?

Valuable pointers come from the defense sector. A new case study, titled Shields Up: How a Military Unit Simultaneously Increased Network Access and Decreased Cyber Risk [PDF], showcases how Authentic8's remote browser isolation technology enabled a U.S. military unit to implement internet policies for personal web access, without increasing the risk of introducing any malware or malicious code into the unclassified network.

The growing need to access publicly available information (PAI) on the web and to leverage the internet for both official and personal business (check out my post on "morale browsing") is making secure access to the broader network a necessity for more military personnel.

"Shields Up" shows how remote browser isolation with Silo Cloud Browser is supporting this change process. Silo enables and secures responsible web use in organizations for which the security risks